T09 · Insecure Skill Coding Practices
- Location
scripts/luis_audio_translator.py:271- Finding
Arbitrary Recursive Directory Deletion Through split --clean
- Content
View full analysis
Vulnerability Details
File Location:
scripts/luis_audio_translator.py, lines 271-274
Vulnerability Type: Unrestricted recursive directory deletion
Risk Level: Highpython output_dir = Path(args.output_dir or input_path.parent / f"{input_path.stem}_分割") if output_dir.exists() and args.clean: shutil.rmtree(output_dir) output_dir.mkdir(parents=True, exist_ok=True)Technical Analysis
The
splitcommand accepts an arbitrary path through--output-dir. When the--cleanoption is also supplied, the implementation passes that path directly toshutil.rmtree().The path is not canonicalized or checked against an approved output boundary. The code also does not verify that the directory was created by this Skill, contains only prior split results, or is safe to remove. There are no protections against selecting a filesystem root, home directory, project directory, input directory, or another unrelated directory.
This creates a destructive path-manipulation vulnerability. Although exploitation requires control over or influence upon the command arguments, Agent-generated command lines may incorporate attacker-controlled instructions or paths. No command injection is required.
Attack Path
-
An attacker influences the user or Agent to invoke the
splitoperation on a valid media file. -
The attacker supplies an existing valuable directory as
--output-dir. -
The attacker causes the invocation to include
--clean, for example:text python scripts/luis_audio_translator.py split input.mp3 --segment-seconds 300 --format mp3 --output-dir /path/to/valuable-directory --clean -
The application confirms only that the selected path exists.
-
Before FFmpeg processing starts,
shutil.rmtree(output_dir)recursively deletes the selected directory. -
The application recreates an empty directory at the same path and proceeds with the split operation, potentially obscur ...[truncated 597 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Avoid recursively deleting a user-selected output directory. Delete only files known to have been generated by a previous split operation.
- Resolve the output path with
Path.resolve()and reject dangerous targets, including filesystem roots, the user's home directory, the input file's parent directory, the project directory, and other protected locations. - Create a dedicated subdirectory for every split operation rather than cleaning an arbitrary caller-provided directory.
- Place a Skill-specific marker file in generated directories and permit cleanup only when that marker is present and valid.
- Refuse cleanup if the target path or any relevant path component violates the expected directory policy.
- Require explicit interactive confirmation for destructive cleanup when interactive execution is available.
- Use a safe cleanup routine that enumerates and validates each expected generated file instead of calling
shutil.rmtree()on the entire directory. - Add tests covering dangerous values such as filesystem roots, home directories, relative traversal paths, the input directory, and unrelated pre-existing directories.
